Skip to main content
How It WorksSandboxPricing
← Trust Center

DATA PRACTICES

What RANKIGI stores. What RANKIGI never stores.

You are the data controller. RANKIGI is the data processor. Here is exactly what that means.

What We Store

Data TypeWhat We StoreWhat We Never Store
Agent eventsSHA-256 hashes of inputs/outputsRaw content
Decision metadataAction type, tool, timestampsModel outputs, reasoning text
Agent identityPassport metadata, scopeAgent code, model weights
Human accountabilityOwner name, role, acceptance datePasswords, personal data
CertificatesNumber, scores, hashes, datesNothing additional

Data Retention by Tier

TierRetentionAfter Subscription End
Free30 daysDeleted
Starter90 daysDeleted
Pro1 yearDeleted within 90 days
Production2 yearsDeleted within 90 days
EnterpriseCustom (2yr+ default)Configurable

Data Residency

RANKIGI processes and stores data in the United States (AWS us-east-1 via Supabase). Enterprise tier customers can request EU (Frankfurt) or other regions. For EU customers, RANKIGI relies on Standard Contractual Clauses (SCCs). Our DPA is available at rankigi.com/dpa.

Breach Notification Protocol

Within 1 hour: incident response activated. Within 4 hours: affected customers notified. Within 24 hours: public incident report. Within 72 hours: full post-mortem (GDPR requirement).

Because RANKIGI stores only hashes, a breach does not expose your sensitive data. A notification means hash records were accessed — not the actions themselves.

Your Rights

As data controller you have rights to: access, deletion, portability (JSON export), correction, and restriction. Email privacy@rankigi.com. We respond within 30 days.

Sub-processors

SupabaseDatabase and authenticationUnited States
RailwayApplication hostingUnited States
StripePayment processingUnited States
ResendTransactional emailUnited States

We notify customers of new sub-processor additions 30 days in advance.